LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-07-2010, 08:12 AM   #1
jnreddy
Member
 
Registered: May 2008
Location: INDIA
Distribution: RHEL
Posts: 171

Rep: Reputation: 15
which is secure ftp or pam


Dear Friends

I want to restrict a user accessing my ftp site.

1) i can block the user in ftp configuration file

2) i can block the user in PAM or /etc/host.deny

i heard that if pam is denying the user and ftp is allowing the user
the user can get the access it means that ftp conf file is stronger than host.deny


which one really block the user.


Thanks In Advance
Jnreddy
 
Old 05-07-2010, 08:52 AM   #2
centosboy
Senior Member
 
Registered: May 2009
Location: london
Distribution: centos5
Posts: 1,137

Rep: Reputation: 116Reputation: 116
Quote:
Originally Posted by jnreddy View Post
Dear Friends

I want to restrict a user accessing my ftp site.

1) i can block the user in ftp configuration file

2) i can block the user in PAM or /etc/host.deny

i heard that if pam is denying the user and ftp is allowing the user
the user can get the access it means that ftp conf file is stronger than host.deny


which one really block the user.
deny ftp user in here



Thanks In Advance
Jnreddy


Code:
/etc/ftpd/ftpusers
just add the username to deny on a sep line
 
1 members found this post helpful.
Old 05-08-2010, 03:21 AM   #3
jnreddy
Member
 
Registered: May 2008
Location: INDIA
Distribution: RHEL
Posts: 171

Original Poster
Rep: Reputation: 15
Thank you

Dear centosboy

Thank you for your reply

as you said i can deny the user.

which one is more secure

Thanks In Advance
Jnreddy
 
Old 05-08-2010, 04:24 AM   #4
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 681Reputation: 681Reputation: 681Reputation: 681Reputation: 681Reputation: 681
The hosts.deny file will block access to a service from a certain IP address. The ftpusers file will block access to users on the system listed in the file. It will contain for example system users who shouldn't be accessing the ftp service. pam_access (/etc/security/access.conf) can restrict certain users, and can include what kind of access is allowed. For example, it can restrict logins on certain terminals.

Be sure to read the proftp documentation, the hosts_access, pam_access and access.conf man pages. If your service uses xinetd instead of standalone, read the xinetd.access man page.
 
Old 05-09-2010, 05:23 AM   #5
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 681Reputation: 681Reputation: 681Reputation: 681Reputation: 681Reputation: 681
Moved: This thread is more suitable in Linux Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
1 members found this post helpful.
Old 05-10-2010, 02:59 AM   #6
jnreddy
Member
 
Registered: May 2008
Location: INDIA
Distribution: RHEL
Posts: 171

Original Poster
Rep: Reputation: 15
Thankyou

Dear Centosboy,jschiwal

Thank you for your kind reply i will try what you said.

one more thing i thanked so many people for their valuable answers
why its showing i thanked zero. please let me know mt thanks are going are going wasted.

Thanks & Regards
JNReddy
 
Old 05-10-2010, 04:03 AM   #7
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by jnreddy View Post
one more thing i thanked so many people for their valuable answers
why its showing i thanked zero. please let me know mt thanks are going are going wasted.
Your profile lists twelve posts thanked by you.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Secure FTP pedrokoma Linux - Security 1 04-12-2010 03:31 PM
LXer: Set up a virtual FTP server with pam-mysql LXer Syndicated Linux News 0 02-08-2008 06:20 PM
pure-ftp - pam smb_auth - nsswitch problem collen Linux - Security 1 03-05-2007 06:57 AM
pure-ftp with PAM auth. 530 Erron on Debian danwald79 Linux - Server 2 02-24-2007 02:22 AM
PAM - Secure or Cleartext? bfloeagle Linux - Security 2 11-05-2001 11:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration